ROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEX
25 August 2023, 04:53 AM | #1 |
"TRF" Member
Join Date: Jan 2011
Location: CA, USA
Watch: Out!!!
Posts: 6,474
|
Potential Fraud Opportunity -- Synchrony Bank
Curious if anyone else here uses Synchrony Bank?
Their online login always used to send me a one-time password when I attempted to log in, and of course, it sent it to the number on file. I tried to login yesterday (used the url from the statement), and now it's asking me to enter the phone number to use to send the one-time password. That doesn't make sense to me, because they are supposed to send it to my phone number to validate my account, not to any number I give them. I held off on entering the phone number, called Customer Service (phone number from the statement) and they didn't seem to think it was an issue. Am I being over-cautious? There are so many forms of fraud these days, I don't think I can be too careful. |
25 August 2023, 05:11 AM | #2 | |
"TRF" Member
Join Date: Mar 2017
Real Name: Varies
Location: On a couch
Watch: Me
Posts: 380
|
Quote:
It’s a way for banks to periodically check that the number on file is correct. That’s my best guess here, FWIW. |
|
25 August 2023, 05:11 AM | #3 |
"TRF" Member
Join Date: Nov 2015
Real Name: Charlie
Location: Miami
Posts: 1,534
|
I would be cautious
__________________
I have all the grails I could ever want, but the hunt will always continue . |
25 August 2023, 07:14 AM | #4 |
"TRF" Member
Join Date: May 2023
Location: USA
Posts: 110
|
I’m a retired IT security exec and it is fishy to me too. They should already have your cell # in the database. Asking for you to enter the last 4 numbers is done sometimes as confirmation but letting a potential hacker put in his own number to access your account is not something any company would do. Are you sure you are on the legitimate web site and is it https?
Sent from my iPad using Tapatalk |
25 August 2023, 07:49 AM | #5 |
2024 SubLV41 Pledge Member
Join Date: Sep 2008
Location: New Mexico
Watch: Seiko #SRK047
Posts: 34,460
|
I wouldn't do it.
__________________
JJ Inaugural TRF $50 Watch Challenge Winner |
25 August 2023, 07:54 AM | #6 |
2024 SubLV41 Pledge Member
Join Date: Dec 2010
Real Name: PaulG
Location: Georgia
Posts: 42,017
|
Potential Fraud Opportunity -- Synchrony Bank
Do you mean a one-time auth code after you have entered a valid userID and Password? (Also known as two-factor authentication)
Sent from my iPhone using Tapatalk Pro
__________________
Does anyone really know what time it is? |
25 August 2023, 08:54 AM | #7 |
"TRF" Member
Join Date: Jan 2011
Location: CA, USA
Watch: Out!!!
Posts: 6,474
|
Yes. If it's a phony site, they already have my Login and Password. All they need is to be able to clone my cell and they can get into my real account.
|
25 August 2023, 08:57 AM | #8 |
2024 SubLV41 Pledge Member
Join Date: Dec 2010
Real Name: PaulG
Location: Georgia
Posts: 42,017
|
Yes - that is a possibility.
If you’re concerned, perhaps log-in directly from your web browser. Be sure https: is in the web url. Then change your password online. That should give you some peace of mind. Sent from my iPhone using Tapatalk Pro
__________________
Does anyone really know what time it is? |
25 August 2023, 08:57 AM | #9 | |
"TRF" Member
Join Date: Jan 2011
Location: CA, USA
Watch: Out!!!
Posts: 6,474
|
Quote:
|
|
25 August 2023, 09:03 AM | #10 |
"TRF" Member
Join Date: Jan 2011
Location: CA, USA
Watch: Out!!!
Posts: 6,474
|
I tried using a different phone number and it would not accept it.
|
25 August 2023, 09:07 AM | #11 |
"TRF" Member
Join Date: Jan 2011
Location: CA, USA
Watch: Out!!!
Posts: 6,474
|
After verifying that the site would not send a Two-Factor Authentication Code to a number that was not associated with my account, I made the choice to enter my number and I received the code and logged in normally.
Changed my password and hope all is well, I'll keep my eye on it daily. |
25 August 2023, 09:34 AM | #12 |
2024 ROLEX SUBMARINER 41 Pledge Member
Join Date: Jul 2010
Location: Denver
Posts: 4,284
|
All two factor authentication tools I use block out all but the last two or four digits of the phone number I want it sent to. None ask for the whole number so I would definitely change user ID and Password.
__________________
Jason 116610 LN DateJust Pelagos FXD |
25 August 2023, 09:38 AM | #13 |
2024 SubLV41 Pledge Member
Join Date: Mar 2017
Location: United States
Watch: Rolex and Patek
Posts: 11,427
|
A lot of times it is a phony scam site posing as the bank. This bank is fine.
|
25 August 2023, 10:39 AM | #14 | |
"TRF" Member
Join Date: May 2023
Location: USA
Posts: 110
|
Quote:
Ok, as you already know you need to call them, tell them what happened and have them help you reset your password. You should be fine wrt financials. Don’t worry they deal with this all the time. Sent from my iPad using Tapatalk |
|
25 August 2023, 10:54 AM | #15 |
2024 Pledge Member
Join Date: Oct 2011
Real Name: Seth
Location: nj
Watch: Omega
Posts: 24,834
|
__________________
If happiness is a state of mind, why look anywhere else for it? IG: gsmotorclub IG: thesawcollection (Both mostly just car stuff) |
25 August 2023, 02:51 PM | #16 |
"TRF" Member
Join Date: Nov 2010
Real Name: Jeff
Location: Arizona
Watch: is recovered!!
Posts: 4,255
|
I recommend using their phone app. I’ve never had an issue.
__________________
16753 GMT Master, 16613 Bluesy, 16710 GMT Master II, 16570 Polar Explorer II-Stolen & Recovered!! Card Carrying Member of the Global Assoc. of Retro-Grouch-Curmudgeons |
25 August 2023, 10:57 PM | #17 |
"TRF" Member
Join Date: Dec 2010
Real Name: Yuri
Location: New Jersey
Watch: Sub-C Date, Pepsi
Posts: 1,361
|
|
25 August 2023, 11:09 PM | #18 |
2024 SubLV41 Pledge Member
Join Date: Nov 2007
Location: San Francisco, CA
Watch: Date & No Date
Posts: 10,868
|
I would download their app, they must have one. Impossible to have a fake app on App Store. You’ll still probably have to authenticate via mobile phone (don’t use land line phone), or by email, a.k.a., two-factor authentication) as 77T mentioned above. Pretty common these days and good security
__________________
"You might as well question why we breathe. If we stop breathing, we'll die. If we stop fighting our enemies, the world will die." Paul Henreid as Victor Laszlo in Casablanca |
26 August 2023, 06:33 AM | #19 | |
2024 SubLV41 Pledge Member
Join Date: Jun 2020
Real Name: Omar
Location: somewhere
Watch: 126515LN (sundust)
Posts: 1,309
|
Quote:
|
|
26 August 2023, 12:26 PM | #20 |
"TRF" Member
Join Date: Mar 2022
Location: Nashville, TN
Posts: 336
|
I knew what you meant on a Rolex forum, but far from universally true.
https://techviral.net/identify-fake-...le-play-store/ |
26 August 2023, 02:36 PM | #21 | |
2024 SubLV41 Pledge Member
Join Date: Nov 2007
Location: San Francisco, CA
Watch: Date & No Date
Posts: 10,868
|
Quote:
__________________
"You might as well question why we breathe. If we stop breathing, we'll die. If we stop fighting our enemies, the world will die." Paul Henreid as Victor Laszlo in Casablanca |
|
26 August 2023, 07:27 PM | #22 |
2024 ROLEX SUBMARINER 41 Pledge Member
Join Date: Jan 2018
Location: Florida
Watch: Sub, DJ41, GMT
Posts: 8,267
|
Potential Fraud Opportunity -- Synchrony Bank
If I read this right, you used the URL from a statement, and the statement looks legitimate, right?
Basically, the URL and integrity of the statement is being questioned here… So if a fraudster was able to recreate your statement, with account number, transactions, and all the correct data, then you’re already TOTALLY SCREWED. They have all the information they need for stealing your money and identity. There is no need for them to contact you or “phish” for your username and password. It would be stupid for them to do so. This is why I think you’re okay. It sounds legit. Also it’s not uncommon for companies to change their security processes from time-to-time and ask for cell phone info again even if it’s already on file. With all that said, NEVER EVER click on a strange or suspicious URL. Btw, I’m a technology executive for a bank…so I do have expertise in this field. Sent from my iPhone using Tapatalk |
26 August 2023, 08:58 PM | #23 |
2024 SubLV41 Pledge Member
Join Date: Jul 2013
Real Name: Brian (TBone)
Location: canada
Watch: es make me smile
Posts: 78,126
|
Why are there so many bad people out there
Hope you get it sorted OP |
29 August 2023, 12:36 AM | #24 | |
"TRF" Member
Join Date: Mar 2011
Real Name: Michael
Location: RTP, NC, USA
Watch: ♕& Ω
Posts: 5,221
|
Quote:
Everyone else though, take note of this and be careful out there! Just recently my mother was almost taken in by a scam, but fortunately she called me first and I told her to stop. She nearly sent in $20K+ just because these scammers are getting more and more sophisticated and clever. I also work in I/T and I have a good idea of how most of this stuff works. It's scary. I also have the office next to the guy in charge of our network and infrastructure security, and they run tests and scans and hire people to break into our system...
__________________
Enjoy life - it has an expiration date. Disclaimer: Please note that the avatar is not an accurate representation of how I look. The camera adds 10 pounds... |
|
30 August 2023, 01:54 AM | #25 | |
"TRF" Member
Join Date: Jan 2011
Location: CA, USA
Watch: Out!!!
Posts: 6,474
|
Quote:
To alleviate my fears, I typed in a phone number that did not match my cell phone and it was not accepted. This lead me to believe that the site was in fact not compromised in any way. I am very security conscious myself, which is why I questioned when something changed. I have a Yubikey, but unfortunately, not many sites utilize this technology yet. |
|
30 August 2023, 07:24 AM | #26 |
2024 Pledge Member
Join Date: Feb 2020
Real Name: Matt
Location: .
Watch: PAM111
Posts: 2,865
|
I misunderstood the title, and thought this was a job listing for a white collar criminal.
|
10 December 2023, 01:52 PM | #27 | |
"TRF" Member
Join Date: Dec 2023
Location: N. California
Posts: 1
|
Synchrony has a bizarre way of choosing eligible phone numbers for 2FA.
Quote:
She's a beneficiary, and we live together, but that's it. Synchrony has a bizarre way of choosing eligible phone numbers for 2FA. Before the current system, they provided a drop-down list with phone numbers they gleaned from credit companies, etc., most of them long ago disconnected and now belonging to random strangers. I'm trying to find out from them why they don't just use the phone number(s) provided to them by the account owner(s). |
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
|
|
*Banners
Of The Month*
This space is provided to horological resources.